Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- MW3ProjectMemoriesV3 & MW2RebornV3 By Enstone:
- ######################################################
- MW3Memories:
- Antidump - DBA0A0
- CISC VM pointer - 00DBE7A4
- TM_WL_2: 00DBC87C
- ######################################################
- MW2RebornV3:
- Antidump - DCA0A0
- CISC_VMware - 00DCE505
- ######################################################
- //PwN3D By BaSs_HaXoR
- Log data
- Address Message
- 02D40118 Breakpoint at 02D40118
- -------------- File Info -------------
- FIRST_PATH:
- C:\Users\BaSs_HaXoR\Desktop\FMT Tools Ready for Cracking\MW2RebornV3.exe
- MAIN_PATH:
- C:\Users\BaSs_HaXoR\Desktop\FMT Tools Ready for Cracking\MW2RebornV3.exe
- FIRST_FILE_NAME:
- MW2RebornV3.exe
- FIRST_FILE_END:
- exe
- FIRST_NAME:
- MW2RebornV3
- ----------******************----------
- Found 0 dec & 0 hex Active Processes!
- ----------******************----------
- ----------- TLS MAIN INFOS -----------
- TLS TABLE RVA: B88D44 & SIZE: 18
- TLS TABLE VA: F88D44 & SIZE: 18
- DATABLOCKSTART VA: D7F019
- DATABLOCKEND VA: D7F01C
- INDEXVARIABLE VA: D72CFC
- CALLBACKTABLE VA: D7E020
- NO CALLBACK INSIDE PRESENT
- ----------******************----------
- PLUGINPATH: C:\Users\BaSs_HaXoR\Desktop\Deobfuscation\OllyDebugger shit\OllyDebugger
- ------------ Plugin List -------------
- No: PLUGIN-NAME
- ----------******************----------
- VM antidump redirector is used.
- Version retriever is not used.
- Oreans kernel32, user32 and advapi32 dll's are disabled.
- -------------
- Modulebase: 00400000
- Code & IAT Section: 00401000
- Found new Anti-Dump store location at address: DCA0A0
- 00FD3020 Breakpoint at MW2Rebor.00FD3020
- 00FD3005 Breakpoint at MW2Rebor.00FD3005
- 6EAF0000 Module C:\WINDOWS\SYSTEM32\ntmarta.dll
- 74800000 Module C:\WINDOWS\SYSTEM32\winmm.dll
- 741E0000 Module C:\WINDOWS\SYSTEM32\WINMMBASE.dll
- 75830000 Module C:\WINDOWS\SYSTEM32\cfgmgr32.dll
- 77038B90 Hardware breakpoint 1 at KERNEL32.VirtualAlloc
- ----------------------------
- VMware check pointer was found and patched at: 00DCE505
- ----------------------------
- CISC VM is located in the Themida - Winlicense section.
- ----------------------------
- VMware check pointer was found and patched at: 00DCE505
- ----------------------------
- TM_WL_2: 00DCCACA
- #################### MW2 Reborn ####################
- ---------------EX--------------------------------------
- Call from: DCF085 | API: 77038B90 | NAME: VirtualAlloc
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0CF92 | API: 77038F80 | NAME: LoadLibraryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0CFB0 | API: 77038F80 | NAME: LoadLibraryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0CFC4 | API: 7703A940 | NAME: GetLocalTime
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0EA3B | API: 758E75A0 | NAME: MessageBoxExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0F2ED | API: 77048920 | NAME: CreateFileA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E10CDA | API: 75A3C620 | NAME: RegCreateKeyA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E10CF9 | API: 75A2E120 | NAME: RegFlushKey
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E10D18 | API: 75A26FB0 | NAME: RegSetValueExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E10D37 | API: 75A19330 | NAME: RegCloseKey
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E10D56 | API: 75A194B0 | NAME: RegQueryValueExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11155 | API: 7703B5A0 | NAME: GetCommandLineA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19CFB | API: 77048880 | NAME: SetEvent
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19D19 | API: 770488C0 | NAME: WaitForSingleObject
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19D37 | API: 77048740 | NAME: CreateEventA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19D55 | API: 77038F80 | NAME: LoadLibraryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19D73 | API: 7703A790 | NAME: FreeLibrary
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19D91 | API: 77037B50 | NAME: GetProcAddress
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19DAF | API: 7703B2E0 | NAME: GetEnvironmentVariableA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19DCD | API: 7589C850 | NAME: wsprintfA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19DEB | API: 7703B5B0 | NAME: GetVersion
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19E09 | API: 77048920 | NAME: CreateFileA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19E27 | API: 77049850 | NAME: ExitProcess
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19E45 | API: 77038A50 | NAME: DeviceIoControl
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19E5C | API: 75A26BB0 | NAME: RegOpenKeyA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19E7A | API: 770486F0 | NAME: CloseHandle
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19E98 | API: 77038F20 | NAME: VirtualFree
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E19EB6 | API: 770382D0 | NAME: Sleep
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E1806D | API: 77038B10 | NAME: GetVersionExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E18A06 | API: 75A19330 | NAME: RegCloseKey
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E18A80 | API: 75A194B0 | NAME: RegQueryValueExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E1EB91 | API: 770382D0 | NAME: Sleep
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E21FB6 | API: 77048920 | NAME: CreateFileA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E21FC0 | API: 77048AF0 | NAME: GetFileSize
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E21FCA | API: 77038B90 | NAME: VirtualAlloc
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E21FD4 | API: 77048C00 | NAME: ReadFile
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E21FDE | API: 77038B10 | NAME: GetVersionExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E21FF2 | API: 7703A890 | NAME: GetSystemDirectoryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E2202E | API: 770486F0 | NAME: CloseHandle
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E30FB8 | API: 77032410 | NAME: IsBadReadPtr
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3306C | API: 7726D7B0 | NAME: NtOpenThread
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E335A8 | API: 74802800 | NAME: timeGetTime
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E573D8 | API: 770431B0 | NAME: Process32Next
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AF5E | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AFE9 | API: 77032410 | NAME: IsBadReadPtr
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3B1E0 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AF5E | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3B1E0 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AF5E | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3B1E0 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AF5E | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3B1E0 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AF5E | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3B1E0 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AF5E | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3B1E0 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E3AF5E | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E3B1E0 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E6068C | API: 7726C800 | NAME: ZwQueryInformationProcess
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E62BF0 | API: 7726C740 | NAME: ZwSetInformationThread
- -------------------------------------------------------
- #################### MW3 MEMORIES ####################
- ---------------EX--------------------------------------
- Call from: DBF275 | API: 77038B90 | NAME: VirtualAlloc
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: DFCE9D | API: 77038F80 | NAME: LoadLibraryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: DFCEBB | API: 77038F80 | NAME: LoadLibraryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: DFCECF | API: 7703A940 | NAME: GetLocalTime
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: DFF09F | API: 758E75A0 | NAME: MessageBoxExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E00CAE | API: 75A3C620 | NAME: RegCreateKeyA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E00CCD | API: 75A2E120 | NAME: RegFlushKey
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E00CEC | API: 75A26FB0 | NAME: RegSetValueExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E00D0B | API: 75A19330 | NAME: RegCloseKey
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E00D2A | API: 75A194B0 | NAME: RegQueryValueExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E00EAE | API: 77048920 | NAME: CreateFileA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E01F2E | API: 7703B5A0 | NAME: GetCommandLineA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E099B8 | API: 77048880 | NAME: SetEvent
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E099D6 | API: 770488C0 | NAME: WaitForSingleObject
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E099F4 | API: 77048740 | NAME: CreateEventA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09A12 | API: 77038F80 | NAME: LoadLibraryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09A30 | API: 7703A790 | NAME: FreeLibrary
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09A4E | API: 77037B50 | NAME: GetProcAddress
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09A6C | API: 7703B2E0 | NAME: GetEnvironmentVariableA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09A8A | API: 7589C850 | NAME: wsprintfA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09AA8 | API: 7703B5B0 | NAME: GetVersion
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09AC6 | API: 77048920 | NAME: CreateFileA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09AE4 | API: 77049850 | NAME: ExitProcess
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09B02 | API: 77038A50 | NAME: DeviceIoControl
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09B19 | API: 75A26BB0 | NAME: RegOpenKeyA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09B37 | API: 770486F0 | NAME: CloseHandle
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09B55 | API: 77038F20 | NAME: VirtualFree
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E09B73 | API: 770382D0 | NAME: Sleep
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E07DEF | API: 77038B10 | NAME: GetVersionExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0B965 | API: 75A19330 | NAME: RegCloseKey
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0B9DF | API: 75A194B0 | NAME: RegQueryValueExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E0F535 | API: 770382D0 | NAME: Sleep
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11D2B | API: 77048920 | NAME: CreateFileA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11D35 | API: 77048AF0 | NAME: GetFileSize
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11D3F | API: 77038B90 | NAME: VirtualAlloc
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11D49 | API: 77048C00 | NAME: ReadFile
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11D53 | API: 77038B10 | NAME: GetVersionExA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11D67 | API: 7703A890 | NAME: GetSystemDirectoryA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E11DA3 | API: 770486F0 | NAME: CloseHandle
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E1FCD0 | API: 77032410 | NAME: IsBadReadPtr
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E21EBA | API: 7726D7B0 | NAME: NtOpenThread
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E224ED | API: 74802800 | NAME: timeGetTime
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E46126 | API: 770431B0 | NAME: Process32Next
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E47352 | API: 7726C800 | NAME: ZwQueryInformationProcess
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28CF7 | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28DD8 | API: 77032410 | NAME: IsBadReadPtr
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E290F5 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28CF7 | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E290F5 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28CF7 | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E290F5 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28CF7 | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E290F5 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28CF7 | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E290F5 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28CF7 | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E290F5 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E28CF7 | API: 7703FA50 | NAME: lstrcmpiA
- -------------------------------------------------------
- ---------------GPA---------------------------------
- Call from: E290F5 | API: 7726C9D0 | NAME: NtQuerySystemInformation
- -------------------------------------------------------
- ---------------EX--------------------------------------
- Call from: E51FB0 | API: 7726C740 | NAME: ZwSetInformationThread
- -------------------------------------------------------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement